daily

2026-07-27
1

Wexford housing development at Mulgannon

Wexford Local · original → · 8/10 · Local Wexford housing development, highest priority category
[image →]Pictured at Roxborough Manor, Mulgannon, Wexford are (left to right); Senator Cathal Byrne, Cllr Jim Codd, Eamonn Hore, Director of Services Wexford County Council, Cllr Catherine ‘Biddy’…
[image →]
Pictured at Roxborough Manor, Mulgannon, Wexford are (left to right); Senator Cathal Byrne, Cllr Jim Codd, Eamonn Hore, Director of Services Wexford County Council, Cllr Catherine ‘Biddy’ Walsh, Stephen McDonald, Colm Neville Construction, Cllr Lisa McDonald, Cathaoirleach Wexford County Council, Minister for Housing, Local Government and Heritage James Browne TD, Mayor of Wexford Cllr Vicky Barron, George Lawlor TD, Cllr John Fleming, Cllr Garry Laffan, Colm Neville and Stephen O’Connor, Senior Executive Officer Wexford County Council. (Pic; WexfordLocal.com)

By Dan Walsh at Mulgannon, Wexford town.

Minister for Housing, Local Government and Heritage was in Wexford town recently at Roxborough Manor, Mulgannon, where Wexford County Council continues to expand the supply of affordable housing while creating new pathways to home ownership for first-time buyers.

Wexford County Council has maintained strong momentum in the delivery of affordable housing since the beginning of 2025, the latest projects will constitute the eighth rollout under the Council’s affordable housing programme, reflecting its ongoing commitment to increasing housing availability and supporting affordable homeownership opportunities.

Looking ahead, a further opportunity for affordable home ownership will become available with the launch of Roxborough Manor, Mulgannon, Wexford Town, in early September 2026.

2

State takes in record €5.9bn in environmental taxes in 2025

Breaking News Ireland · original → · 7/10 · Irish policy: environmental taxes affecting households broadly
The State collected a record €5.9b billion in environment-related taxes last year, with households paying almost €3.5 billion of the total. New figures from the Central Statistics Office (CSO) show…

The State collected a record €5.9b billion in environment-related taxes last year, with households paying almost €3.5 billion of the total. New figures from the Central Statistics Office (CSO) show environmental tax receipts rose by 7 per cent, or approximately €400 million, during 2025. It was the highest amount collected in any year between 2016 and 2025. Households paid 59 per cent of the total, contributing €3.468 billion through taxes and charges on energy, transport and other activities classified as having a negative environmental impact. Energy taxes remained the largest source of revenue, increasing by 12 per cent to €3.924 billion. More than half of that amount came from excise duty on petrol, road diesel, marked gas oil and other hydrocarbon fuels, which generated €2.09 billion. Carbon tax receipts increased by 10 per cent to almost €1.2 billion, while revenue from the Public Service Obligation levy on electricity consumers rose from €63 million to €228 million. CSO statistician Clare O’Hara said the increase was mainly driven by higher receipts from the electricity levy, fuel excise duties and carbon tax. “Environment taxes reached a record €5.9 billion in 2025, increasing by 7 billion, or €0.4 billion, compared with 2024,” she said. Transport taxes, including motor tax and Vehicle Registration Tax (VRT), raised a further €1.925 billion. VRT generated €933 million, while motor tax paid by households and businesses brought in €927 million. Pollution and resource taxes, including the plastic bag and landfill levies, accounted for just €30m, or 0.5 per cent of the total environmental tax take. The record figures come as the Climate Change Advisory Council has urged the Government to continue increasing the carbon tax to €100 per tonne by 2030. In its recommendations for Budget 2027, the council also called for fossil fuel subsidies to be phased out. It criticised emergency reductions in excise duty on petrol and diesel as “insufficiently targeted” and said they were likely to provide the greatest benefit to higher-income households. The current reductions cut excise duty by 27 cent per litre on petrol and 32 cent on diesel. They have been extended until September 1st, after which the previous rates are due to be gradually restored over four months. The extension is expected to cost the Exchequer €270 million. The advisory council said future supports should target vulnerable households and help people permanently reduce their reliance on fossil fuels. It also called for greater transparency around the use of carbon tax revenue, citing findings by the Comptroller and Auditor General that only 61 per cent of ring-fenced receipts were spent on their intended measures between 2020 and 2023. Despite reaching a record amount in cash terms, environmental taxes accounted for 4.3 per cent of total tax revenue in 2025, down from 7.7 per cent in 2016.

3

The relay market powering token resellers and fraud

Hacker News · original → · 7/10 · AI/work tech: token fraud and API security
An Inside Look at the Relay Market Powering Token Resellers and Fraud Matt Lenhard 9 min read My Story I’ve spent a lot of time thinking about token fraud, a problem I first stumbled upon while…

An Inside Look at the Relay Market Powering Token Resellers and Fraud Matt Lenhard 9 min read My Story I’ve spent a lot of time thinking about token fraud, a problem I first stumbled upon while working as a software engineer on an AI gateway. We faced constant abuse. At first it was free-credit abuse, where users spun up accounts en masse. Then it was our support chatbot. I started talking to friends about it and hearing stories of companies losing millions of dollars to abuse each day. The abuse took a number of different shapes, and the abusers were relentless. I came to realize that the problem was much bigger than us. A new form of fraud had emerged, and it had become endemic to the token economy. While researching where the abuse was coming from, I stumbled onto a Chinese forum where operators openly discussed the relays and their methods. My notes on the industry and its players are below. So What Is a Relay? A relay — or “transfer station” — is essentially a service that proxies traffic to U.S. models, often at a deep discount. For example, one operator’s price-comparison site listed a package that bought the equivalent of $3,333 worth of official Anthropic credit for 425 RMB — roughly $0.13 of usage per $1 spent. To make that concrete, here’s how far below official pricing the relays we track actually run, ranked by discount: - 01Now Coding97.8% - 02I Code Easy97.1% - 03Claude ZZ96.6% - 04Doro96.4% - 05UoCode96.3% - 06ZeroCode94.9% - 07AiYa94.9% - 08HongMaCC94.2% - 09Right Code94.1% - 10BUZZ94.1% How the Market Works The ecosystem runs four layers deep, from the merchants sourcing raw accounts down to the developers buying cheap tokens: Card & account merchants — virtual credit cards built to pass U.S. and European billing checks, plus bulk-registered accounts. Account pools — aggregate hundreds of upstream accounts, manage tokens and rate limits, handle failover, and expose a single API. Relays / transfer stations — wrap the pool's API in a clean, billed, Chinese-language product and compete on price. Developers, startups, and SaaS chasing cheap inference — plus commercial buyers running model distillation. Upstream Sitting at the top are the card merchants (卡商) and account merchants (号商). They sell virtual credit cards designed to pass U.S. and European billing checks, along with bulk-registered accounts. Midstream In the middle sit the account pools (账号池). A pool aggregates dozens or hundreds of upstream accounts, manages their authentication tokens and rate limits, handles failover when accounts get flagged, and exposes a single API surface that downstream relays can consume. The inventory isn’t only model-lab accounts. Alongside direct OpenAI, Anthropic, and Google credentials are accounts harvested from the application layer. Much of the forum’s activity centers on “reverse-engineered” access to tools like Kiro and antigravity, which are consumer products, not lab APIs. To a pool, it makes no difference whether a token comes from a lab or from an app built on one; anything that resells or exposes a model is a target. Downstream Downstream sit the relay / transfer stations themselves — the consumer-facing layer. They wrap the pool’s API in a clean Chinese-language product, handle billing and invoicing, run customer-support WeChat groups, and compete on price. End users At the bottom are individual Chinese developers, small startups, and mid-sized SaaS companies hunting for cheap inference — as well as some larger commercial buyers using the infrastructure for model distillation. In practice these layers blur. Many operators run both the pool and the relay, and the forum’s own participants often use “pool” and “transfer station” interchangeably. The Software Behind the Relays Almost every relay I’ve looked at runs on one of two open-source projects: one-api or new-api. Both are OpenAI-compatible gateways. An operator deploys the panel and adds a set of channels (渠道). Each channel represents a provider plus a pool of API keys. The panel exposes a single endpoint that matches the OpenAI API, so buyers just point their existing SDK at the relay’s URL. On every request it pulls a key from the pool, forwards it upstream, returns the response, and deducts quota priced by usage times a multiplier (倍率). It manages the users, tokens, pricing tiers, logs, and billing. new-api is a more actively developed fork of one-api, and the difference is mostly commerce: it ships with self-service payment and recharge, plus image, video, and audio models. Across the relays we track, one-api turns up roughly four times as often as new-api; the original base is the more widespread of the two, even if new-api is the one built to sell. There’s nothing inherently illicit about the software. one-api and new-api are neutral, legitimate tools. Plenty of companies self-host them to put their own accounts behind a single gateway with team quotas and spend tracking. A relay crosses the line when its channels are stocked with stolen, leaked, or pooled keys instead of the operator’s own, and when it resells that access against the providers’ terms. The Methods - Free-trial abuse. Abusers automate account creation en masse to claim free credits, then proxy that traffic back to their own end users. - Chargeback attacks. Abusers charge back their spend after the usage period ends to recoup their costs — or use stolen cards from the start. - Prepaid cards. Abusers fund accounts with prepaid cards capped at a set limit. - Open inference. Any support chatbot without strict guardrails is ripe for having traffic proxied through it. - Denial of wallet. Not strictly a relay technique, but an emerging form of abuse I’ve been tracking: attackers fire off a flood of concurrent requests purely to burn a provider’s spend. It can be facilitated by any of the methods above. The difference is there’s no financial motive. Who Are the Buyers? The three main use cases seem to be cheap tokens, getting around geo-restrictions and model distillation. A few relevant quotes from the forum: A Growing and Maturing Market I was surprised by how mature the market already is. There are price-comparison sites for the relays, affiliate programs, and even gateway products. On the forums, consumer demand looks just as strong. And these aren’t fringe operations: the ten highest-traffic relays we track pull a combined 3.6 million visits a month between them. My hunch is that things get worse for the application layer from here. As Anthropic and others roll out KYC controls and identity verification, the abuse won’t disappear, it will just move somewhere else. They’re Raffling Off Keys Now A clear sign of how normalized this has become is that one of the relay directories runs a daily lottery for API keys. The site — hvoy.ai, which otherwise bills itself as a relay authenticity checker and price-comparison tool, gives away fifty $100 API keys every single day. You earn entry credits from a daily check-in, spend 20 credits per ticket, and can buy up to three tickets a round. On the day I looked, 258 people had entered 401 tickets for the fifty keys. The part that got me is the fairness theater. The draw is provably fair — the same cryptographic scheme legitimate crypto-gambling sites use to prove they didn’t rig the result. The random seed is the hash of the latest Bitcoin block, winners are picked with a Partial Fisher-Yates shuffle, and the full list of entries is published as a snapshot before the draw. How Providers Can Defend Themselves I’ve talked to many companies facing this, and the truth is that there’s no clean fix. Fraud is a constant cat-and-mouse game. What follows isn’t a silver bullet — it’s the set of things that I’ve seen work and that others are doing, roughly in the order that abuse travels: from account creation, to detection and then to damage control. - Raise the cost of entry. Make accounts hard to create in bulk and cap what a fresh one can spend. Check for browser-based automation signals. Any client-side detection can be bypassed, but every bit of friction raises the attacker’s cost. - Watch the money. Flag prepaid cards, virtual cards, mismatched billing info, and small card-testing charges. - Watch the behavior. Look for patterns no real user produces: time from registration to first token, the model selected, prompt relevance (where you can measure it), account age, and IP signals (proxy, VPN, country). - Cluster the accounts. Watch for IP sybils and shared device fingerprints that tie supposedly-separate accounts back to one operator. - Monitor for cost anomalies. Setup monitos and alerts on AI spend as a failsafe, so that you can flip things off if abuse does start. Assume some abuse gets through anyway, and limit what it can cost you: - Enforce spend caps, spend locks, and concurrency limits per account. - Reserve budget for every in-flight request, so concurrent calls can’t blow past your limit. - Start new accounts with low caps; let them earn higher limits with age and a verified card. - If an account’s risk rises mid-session, add friction like a CAPTCHA or an additional form of identity verification. And when you do catch someone, throttle quietly. A clean error just tells the attacker which signal to fix before they come back. None of this stops the abuse for good. But if you make attacking your own service expensive enough that the numbers stop working, they’ll try to find an easier target. Sources All quotes are translated from a V2EX thread in the site’s Programmers section, “A comprehensive guide to AI transfer station jargon,” started by the user v2exgo (who operates the relay at terminal.pub). The thread ran from March 5 to June 23, 2026 and drew roughly 35,000 views and 190 replies. Reply numbers below refer to that thread. - Primary source — V2EX thread: https://www.v2ex.com/t/1196011 - Price-comparison aggregator: getcheapai.com. - Daily API-key lottery: hvoy.ai/free-tokens/lottery — 50 $100 keys drawn per day, settled with a Bitcoin-block-hash seed and a Partial Fisher-Yates shuffle. - Operator’s relay: terminal.pub - Effective-rate derivation: reply #50, where milkleeeeee computes the 425 RMB package as equal to the official $3,333 — about $0.13 per $1 of official usage.

4

Kill The Cookie Banner

Hacker News · original → · 7/10 · EU policy: cookie banner regulation affecting citizens
Stop the tracking circus. Kill the cookie banner! Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never…

Stop the tracking circus. Kill the cookie banner! Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful. We need YOUR help to #KillTheCookieBanner! Cookie banners are made to trick you into waiving your rights You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default. Therefore, the tracking industry needs you to waive your rights. That’s why they invented cookie banners, which often are deliberately misleading as well as annoying. This results in up to 90% of people saying “YES” – even though only around 3% actually want to be tracked online. This system is broken by design. The solution: automatically communicate your privacy preference In Autumn 2025, as part of a bigger legal reform*, the EU Commission finally proposed a solution to the cookie banner problem: automated signals that would communicate your privacy preferences between your device and websites or apps. You could then choose whether you want to accept, refuse, or limit tracking. This idea is neither new nor complex. Your browser already automatically signals other preferences to websites, for example your preferred language. In some US states, such signals for privacy preferences are already legally supported. The tracking lobby fights to keep the cookie banner This would be a simple solution. But the tracking industry seems afraid that if you can express your preferences efficiently, it could result in lower consent rates for tracking. Following lobbying efforts spearheaded by Google and the tracking industry, several Member States are now blocking the EU Commission’s proposal to get rid of the cookie banner. But not only that: industry groups are also lobbying the European Parliament to reject the proposal. We need YOUR help! That’s where you come in: the fight to kill the cookie banner is far from over. The Member States and the European Parliament have not yet decided on their position on the issue yet. You can take action by contacting your representative in the European Parliament or in your Member State and express your frustration. *This proposal for privacy signals is part of an EU law reform called the Digital Omnibus. Most other parts of this reform are problematic and would weaken people’s rights. We want to make clear that we do not support these other aspects of the proposed reform. *This proposal for privacy signals is part of an EU law reform called the Digital Omnibus. Most other parts of this reform are problematic and would weaken people’s rights. We want to make clear that we do not support these other aspects of the proposed reform. With your help, we can kill the cookie banner! Contact your relevant representative in the European Parliament or national government and express your frustration! This initiative is led by civil society organisations across Europe: The initiative is also supported by: Your organisation wants to support this initiative as well? Find out how you can get involved here!

5

Anthropic’s first technical PM on token maxing, the jagged edge, and living in the future | Dianne Penn

Lenny's Newsletter · original → · 7/10 · AI: Anthropic product strategy and token optimization
[image →]Dianne Penn is Head of Product for Anthropic’s AI Research and Labs teams. She joined in 2023 as Anthropic’s first technical product manager, when the entire product team was five…

Dianne Penn is Head of Product for Anthropic’s AI Research and Labs teams. She joined in 2023 as Anthropic’s first technical product manager, when the entire product team was five engineers, and has since helped ship every model from Claude 2 through Fable, and helped incubate Claude Code, MCP, Skills, computer use, tool use, and reasoning. Before Anthropic, she helped build Alexa’s AI at Amazon and, before that, traded high-yield bonds at JP Morgan Chase.

In our in-depth conversation, we discuss:

  1. What Anthropic’s early days were like

  2. The inflection points that turned Anthropic from an underdog into the fastest-growing company in history

  3. How exactly Claude got so good at coding

  4. The eval-driven development loop her team is pioneering

  5. How to find joy in AI when everything is moving this fast

  6. Why Claude’s willingness to push back is key to its success

  7. Where human judgment remains irreplaceable


Brought to you by:

WorkOS—Make your app enterprise-ready, with SSO, SCIM, RBAC, and more

Mercury—Radically different banking, now with Command

Where to find Dianne Penn:

• LinkedIn: linkedin.com/in/dianne-na-penn

Referenced:

• Anthropic: https://www.anthropic.com

• Golden Gate Claude: https://www.anthropic.com/news/golden-gate-claude

• Dario Amodei’s website: https://darioamodei.com

• Scaling Laws and Interpretability of Learning from Repeated Data: https://www.anthropic.com/research/scaling-laws-and-interpretability-of-learning-from-repeated-data

• Tokenmaxxing: How Top Builders Use AI To Do The Work Of 400 Engineers: https://www.ycombinator.com/library/Pa-tokenmaxxing-how-top-builders-use-ai-to-do-the-work-of-400-engineers

• Garry Tan on X: https://x.com/garrytan

• Anthropic co-founder on quitting OpenAI, AGI predictions, $100M talent wars, 20% unemployment, and the nightmare scenarios keeping him up at night | Ben Mann: https://www.lennysnewsletter.com/p/anthropic-co-founder-benjamin-mann

• Anthropic’s CPO on what comes next | Mike Krieger (co-founder of Instagram): https://www.lennysnewsletter.com/p/anthropics-cpo-heres-what-comes-next

• Introducing Labs: https://www.anthropic.com/news/introducing-anthropic-labs

• Louis CK | about airplane Wi Fi: https://www.youtube.com/watch?v=me4BZBsHwZs

• What happens after coding is solved? | Fiona Fung (Manager of the Claude Code and Cowork Teams): https://www.lennysnewsletter.com/p/building-the-most-ai-pilled-engineering

• The Anthropic Hive Mind: https://steve-yegge.medium.com/the-anthropic-hive-mind-d01f768f3d7b

• How to build a company that withstands any era | Eric Ries, Lean Startup author: https://www.lennysnewsletter.com/p/how-to-build-a-company-that-withstands

Fallout on Prime Video: https://www.amazon.com/dp/B0CN4GGGQ2

Fallout (video game): https://fallout.bethesda.net

• Claude Tag: https://www.anthropic.com/news/introducing-claude-tag

Recommended books:

Crucial Conversations: Tools for Talking When Stakes Are High: https://www.amazon.com/dp/0071771328

How to Raise an Adult: Break Free of the Overparenting Trap and Prepare Your Kid for Success: https://www.amazon.com/How-Raise-Adult-Overparenting-Prepare/dp/1627791779

Incorruptible: Why Good Companies Go Bad... and How Great Companies Stay Great: https://www.amazon.com/dp/B0FWZZBPZB


Production and marketing by https://penname.co/. For inquiries about sponsoring the podcast, email podcast@lennyrachitsky.com.

Lenny may be an investor in the companies discussed.


My biggest takeaways from this conversation:

Read more

6

An Inside Look at the Relay Market Powering Token Resellers and Fraud

Simon Willison · original → · 7/10 · AI/work: LLM token fraud and API security
26th July 2026 - Link Blog An Inside Look at the Relay Market Powering Token Resellers and Fraud (via) Fascinating investigation by Matt Lenhard into the market that has grown up around reselling…

26th July 2026 - Link Blog An Inside Look at the Relay Market Powering Token Resellers and Fraud (via) Fascinating investigation by Matt Lenhard into the market that has grown up around reselling LLM tokens at a discount by pooling API keys from various sources. This looks to be mostly a thing in China. Resellers sell access to an LLM proxy that offers significant discounts on regular API pricing, which they achieve by abusing free trials, proxying through unprotected support bots, or sometimes through stolen credit cards or chargeback attacks. The software they are using for these proxies is open source - mostly one-api and its more actively developed fork new-api, both legitimate API proxy products which can be used to load. balance requests across a pool of API credentials. The buyers are seeking cheap tokens, avoiding geo-restrictions, and in some cases collecting data for model distillation. I've been cautious about exposing my own LLM-driven applications publicly out of fear of abuse leading to big token bills. The existence of this marketplace makes me even more cautious: there's now an entire ecosystem that can profit from finding a new unprotected endpoint to exploit. LLM vendors really need to get better at offering strict caps for their API keys. I want my LLM apps to stop working the moment they hit a dollar threshold I've set for a period of time. Here's the (Chinese language) forum thread that served as the principal source for Matt's article. Recent articles - OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened - 22nd July 2026 - A Fireside Chat with Cat and Thariq from the Claude Code team - 21st July 2026 - Kimi K3, and what we can still learn from the pelican benchmark - 16th July 2026

Items scoring 7/10 or above from 11 sources, scored by claude-haiku-4-5-20251001 on relevance to my interests. At most 3 per source.

Scoring categories & sources
  1. Local Wexford or South East Ireland news
  2. Irish or EU-wide affairs affecting citizens broadly: elections, new laws or policy being debated, cost of living, education — especially impacts on mid-life adults or teenagers. Never courts/crime stories.
  3. Irish news on a topic relevant to my interests
  4. Work and tech topics: networking, AI, Kubernetes, platforms, SaaS
  5. AI news including critical or anti-AI perspectives
  6. Gaming: PC gaming, indie gaming, retro gaming
  7. General interests: gardening, woodwork, cycling, fitness, travel
  8. Comics

Sources: Breaking News Ireland, Wexford Local, Hacker News, r/gaming, r/pcgaming, r/antiAI, r/indiegaming, Lenny's Newsletter, One Useful Thing, Newcomer, Simon Willison